The Phishing Kit That Turned Microsoft’s Login Flow Into an AI-Powered Fraud Machine

EvilTokens turns a Microsoft sign-in into a route to corporate email fraud. The phishing kit, first seen in February 2026, tricks people into approving an attacker’s login through a real device code process without handing over a password. The lure usually arrives as an urgent email about an invoice, shared file, document signature or expiring […]

This article has been indexed from Cyber Security News

Read the original article: